Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisorygovernment-vulnerability-catalogactively-exploited-vulnerability

Critical n8n Vulnerabilities Enabling RCE and Sandbox Escapes

Updated 27d agoFirst seen Feb 27, 202637 sources

Government cyber agencies in Belgium and Canada warned that n8n released security updates to address multiple critical vulnerabilities that could allow attackers to compromise workflow automation instances, particularly those exposed to the internet. The advisories emphasize that n8n often orchestrates actions across interconnected systems, increasing blast radius if compromised, and urge administrators to patch immediately to protect confidentiality, integrity, and availability.

The Belgian CCB advisory highlights three critical CVEs—CVE-2026-27495, CVE-2026-27577, and CVE-2026-27497 (each scored CVSS 9.4) affecting n8n versions prior to 2.10.1 / 2.9.3 / 1.123.22, including issues mapped to CWE-94 (code injection) and CWE-89 (SQL injection). It describes sandbox escape leading to arbitrary code execution in the JavaScript Task Runner (notably impacting the default internal Task Runner mode) and abuse of crafted workflow expressions by authenticated users with workflow modification permissions; Canada’s Cyber Centre advisory (AV26-176) additionally enumerates impacted components and attack classes including RCE via Merge Node, expression sandbox escape to RCE, JavaScript Task Runner sandbox escape, unauthenticated expression evaluation via Form Node, and stored XSS across multiple nodes, directing organizations to apply n8n’s upstream fixes.

Share:
Critical n8n Vulnerabilities Enabling RCE and Sandbox Escapes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

18 events from the most recent confirmed update back to the earliest known activity.

18 EVENTS
May 18, 20261mo ago

Researchers disclose three critical n8n node flaws enabling chained RCE

Researchers disclosed three critical n8n vulnerabilities—CVE-2026-44789, CVE-2026-44790, and CVE-2026-44791—affecting the HTTP Request, Git, and XML nodes that low-privileged authenticated users with workflow editing rights could chain to achieve remote code execution. The issues were fixed in versions 1.123.43, 2.20.7, and 2.22.1 and later, with organizations urged to upgrade immediately because no complete workaround exists.

Critical n8n Vulnerabilities Expose Automation Nodes to Full RCE
May 13, 20261mo ago

Canada issues advisory on May n8n security updates

On 2026-05-13, the Canadian Centre for Cyber Security published advisory AV26-459 covering newly released n8n security advisories for multiple critical vulnerabilities. The advisory said affected areas included Pagination Prototype Pollution, Dynamic Credential OAuth Endpoints, Source Control, XML Node Prototype Pollution, and Git Node, and urged users and administrators to review and apply updates.

n8n security advisory (AV26-459) - Canadian Centre for Cyber Security
Apr 22, 20262mo ago

Canada issues advisory on April n8n security updates

On 2026-04-22, the Canadian Centre for Cyber Security published advisory AV26-379 covering newly released n8n security advisories for multiple vulnerabilities, including some rated critical. The advisory said affected areas included MCP Client Registration, dynamic-node-parameters, XML Node Prototype Pollution, XML Webhook, SQL Mode of Merge Node, MCP OAuth client, and Python Task Runner, and urged users to review and apply updates.

n8n security advisory (AV26-379) - Canadian Centre for Cyber Security
Mar 25, 20263mo ago

Canada issues advisory on new n8n security updates

On 2026-03-25, the Canadian Centre for Cyber Security published advisory AV26-278 covering newly released n8n security updates for multiple components and editions, including the Merge Node, Community Edition, Binary Data Inline HTML Rendering, GSuiteAdmin Node, and Form Trigger/Chat Trigger Nodes. The advisory urged users and administrators to review n8n's security information and apply the necessary updates.

n8n security advisory (AV26-278) - Canadian Centre for Cyber Security
Mar 11, 20263mo ago

Pillar Security discloses four critical n8n flaws

On 2026-03-11, Pillar Security publicly detailed four critical n8n vulnerabilities, including CVE-2026-27577 and CVE-2026-27493, which can be exploited individually or chained for remote code execution. The disclosure also warned that attackers could extract the N8N_ENCRYPTION_KEY and decrypt stored credentials such as API keys, OAuth tokens, and database passwords.

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Feb 27, 20264mo ago

Belgium warns users to patch critical n8n vulnerabilities immediately

On February 27, 2026, Belgium's Centre for Cybersecurity published an advisory warning about multiple critical vulnerabilities in n8n and urging immediate patching. This reflects broader government dissemination of the February n8n security issues.

Feb 25, 20264mo ago

n8n releases security updates for multiple critical flaws

On February 25, 2026, n8n released security updates addressing multiple critical vulnerabilities across several components and nodes, including RCE via the Merge Node, sandbox escapes, unauthenticated expression evaluation via the Form Node, and stored XSS issues. Users and administrators were advised to review the advisories and update affected versions.

Feb 4, 20265mo ago

n8n publishes advisory for arbitrary file read by authenticated users

On 2026-02-04, n8n published a GitHub security advisory for an improper file access controls vulnerability that allowed authenticated users to read arbitrary files. This was a separate vendor disclosure from the other n8n advisories and third-party research released the same day.

Improper File Access Controls Allow Arbitrary File Read by Authenticated Users · Advisory · n8n-io/n8n · GitHub

n8n publishes Community Package Installation command injection advisory

On 2026-02-04, n8n published a GitHub security advisory for a command injection vulnerability affecting Community Package Installation. The advisory introduced a separate flaw from the same day's SSH Node arbitrary file write issue and Pillar Security's sandbox-escape disclosures.

Command Injection in Community Package Installation · Advisory · n8n-io/n8n · GitHub

Pillar Security discloses critical n8n sandbox-escape flaws

On 2026-02-04, Pillar Security publicly disclosed two critical sandbox-escape vulnerabilities in n8n, including CVE-2026-25049, that allowed authenticated workflow editors to achieve remote code execution and compromise self-hosted and cloud deployments. The report said n8n acknowledged the issues, rotated secrets, and later delivered a comprehensive fix in version 2.4.0 after an initial December 2025 fix was bypassed.

n8n Sandbox Escape: Critical Vulnerabilities in n8n Exposes Hundreds of Thousands of Enterprise AI Systems to Complete Takeover

n8n publishes SSH Node arbitrary file write advisory

On 2026-02-04, n8n published a GitHub security advisory for an Arbitrary File Write vulnerability affecting the SSH Node that could enable writes on remote systems. This was a separate vendor advisory distinct from the same-day Pillar Security sandbox-escape disclosure and preceded the broader February security update roundup.

Arbitrary File Write on Remote Systems via SSH Node · Advisory · n8n-io/n8n · GitHub
Jan 27, 20265mo ago

JFrog discloses n8n Expression Node remote code execution flaw

On 2026-01-27, JFrog Security Research published a disclosure about a remote code execution vulnerability affecting n8n's Expression Node. The report introduced a distinct technical disclosure separate from earlier January PoC reporting and later February sandbox-escape disclosures.

n8n Expression Node RCE | JFSA-2026-001651697 - JFrog Security Research
Jan 12, 20265mo ago

Canada issues alert on high-severity n8n vulnerabilities

On January 12, 2026, the Canadian Centre for Cyber Security published Alert AL26-001 warning about CVE-2026-21858, CVE-2026-21877, and CVE-2025-68613 affecting the n8n workflow automation platform. The alert described risks including arbitrary code execution and arbitrary file writes, and urged organizations to upgrade or restrict exposed webhook and form endpoints.

Public PoCs emerge for critical n8n vulnerabilities

Public proof-of-concept exploits became available for multiple n8n flaws, including a chain using CVE-2026-21858 and CVE-2025-68613 to achieve unauthenticated remote code execution by extracting sensitive data and executing commands on the server.

Jan 8, 20266mo ago

Critical unauthenticated n8n server-takeover flaw publicly reported

On 2026-01-08, public reporting highlighted a critical n8n vulnerability that could allow unauthenticated attackers to take over exposed servers. This represents an earlier public disclosure of the flaw later reflected in subsequent PoC activity and government warnings.

Critical n8n bug allows unauthenticated server takeover
Dec 26, 20256mo ago

Public GitHub PoC released for CVE-2025-68613 in n8n

On 2025-12-26, a public GitHub repository published exploit code, scanning tools, and research for CVE-2025-68613, a critical expression-injection flaw in n8n. The release made practical exploitation guidance publicly available ahead of later broader reporting on multiple n8n PoCs.

GitHub - TheStingR/CVE-2025-68613-POC: Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance. · GitHub
Dec 24, 20256mo ago

n8n publishes advisory for Legacy Code node file read/write flaw

On 2025-12-24, n8n published a GitHub security advisory for a vulnerability in the Legacy Code node that could enable file read and write access in self-hosted deployments. The advisory introduced a distinct security issue not reflected in the existing timeline entries.

Legacy Code node enables file read/write in self-hosted n8n · Advisory · n8n-io/n8n · GitHub
Oct 30, 20258mo ago

n8n publishes advisory for Git Node pre-commit hook RCE

On 2025-10-30, n8n published a GitHub security advisory for a remote code execution vulnerability in the Git Node involving the pre-commit hook. The advisory represents an earlier distinct disclosure affecting n8n and is separate from later multi-node critical flaw reports.

Remote Code Execution via Git Node Pre-Commit Hook · Advisory · n8n-io/n8n · GitHub
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical n8n Vulnerabilities Enabling RCE and Sandbox Escapes | Mallory